WebLogic T3ÐÒé·´ÐòÁл¯ 0day ©¶´
Ðû²¼Ê±¼ä 2021-04-190x00 ©¶´¸ÅÊö
CVE ID | ʱ ¼ä | 2021-04-19 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà | ÊÇ |
0x01 ©¶´ÏêÇé
½üÈÕ£¬WebLogic±»Åû¶´æÔÚÒ»¸öT3ÐÒé·´ÐòÁл¯0 day©¶´£¬¹¥»÷Õß¿ÉÀûÓôË©¶´Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬Ä¿Ç°¸Ã©¶´´¦ÓÚÔÚÒ°0day״̬£¬¶øÇÒPoC/EXPÒÑÔÚGithubÉϹûÈ»¡£
Ôڸé¶´µÄpocÖУ¬Ê¹ÓÃÁËjava.rmi.MarshalledObjectÀ࣬²¢½«objBytesÊôÐÔ×÷Ϊ·´ÐòÁл¯µÄÁ÷£¬´ÓÖнâÎö¹¤¾ß£¬¿ÉÒÔͨ¹ý°ÑobjBytesÌæ»»ÎªÖ¸¶¨·´ÐòÁл¯¾Í¿ÉÒÔʵÏÖweblogicºÚÃûµ¥Èƹý¡£
0x02 ´¦Öý¨Òé
½¨Ò齫jdkÉý¼¶µ½×îа汾£¬²¢½ûÓÃiiop/t3ÐÒéÒÔ×÷ΪÁÙʱ»º½â´ëÊ©¡£
½ûÓÃT3ÐÒ飬¾ßÌå²Ù×÷ÈçÏ£º
1£©½øÈëWebLogic¿ØÖÆÌ¨£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°Äþ¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£
2)ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ)¡£
3£©Éú´æºóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£
½ûÓÃIIOPÐÒ飬¾ßÌå²Ù×÷ÈçÏ£º
µÇ½WebLogic¿ØÖÆÌ¨£¬base_domain >·þÎñÆ÷ÌáÒª >AdminServer
ÏÂÔØÁ´½Ó£º
https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html
0x03 ²Î¿¼Á´½Ó
https://github.com/hhroot/2021_Hvv/commit/8dcfdd7786ded69f404d52a162a8c4dfcbfd34b9
https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html
0x04 ʱ¼äÏß
2021-04-18 Ñо¿ÈËÔ±Åû¶©¶´
2021-04-19 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/